Executive brief
A vulnerability in the Android System component could allow an attacker to cause a device to become unresponsive or crash. This occurs due to improper resource management when the system processes certain image-related data in the launcher. An exploit could lead to a denial of service, disrupting normal operations for the user without requiring any special permissions or user interaction.
Technical details
A denial of service vulnerability exists in the 'getPreferredSize' function within 'LauncherProcessImageListener.kt' of the Android System component. The flaw is rooted in improper resource management that can lead to resource exhaustion. A local attacker can exploit this vulnerability without any additional execution privileges or user interaction to cause a denial of service (DoS) on the affected device. The issue is addressed in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later. Affected AOSP versions include 14, 15, 16, and 16-qpr2.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
- 2026-06-01: disclosed